AmerisourceBergen · Vulnerability Disclosure

Amerisourcebergen Vulnerability Disclosure

Vulnerability disclosure

AmerisourceBergen runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Pharmaceutical DistributionHealthcareDrug DistributionManufacturer SolutionsProvider SolutionsAnimal HealthLife SciencesFortune 100
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security-disclosures@cencora.com

Source

Vulnerability Disclosure

amerisourcebergen-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-02'
method: searched
probe: true
source: https://www.cencora.com/responsible-disclosure
note: >-
  Cencora (formerly AmerisourceBergen) publishes a full Responsible Security Disclosure
  program: scope, researcher guidelines, excluded submission types, a stated remediation
  workflow, and an explicit good-faith safe harbour. Reports go through a web form, with
  security-disclosures@cencora.com given as the fallback when the form is unavailable.
  There is no bug-bounty platform (no HackerOne / Bugcrowd / Intigriti listing) and no
  /.well-known/security.txt is served on any Cencora host — the program is discoverable
  only from the site footer.
policy:
  - https://www.cencora.com/responsible-disclosure
contact:
  - security-disclosures@cencora.com
submission_channel: web form at https://www.cencora.com/responsible-disclosure
bug_bounty: false
security_txt: false
safe_harbor: true
scope: >-
  Internet-accessible systems, applications, websites and services that Cencora owns and
  operates. Third-party or partner-operated systems are out of scope unless Cencora
  explicitly names them as eligible.
excluded:
  - Informational or best-practice findings with no demonstrated security impact
  - Unvalidated automated scanner output
  - Missing headers, TLS/certificate observations, version disclosure, DNS or email-auth
    configuration, clickjacking and similar hardening issues with no realistic attack scenario
  - Denial-of-service, load, stress and resource-exhaustion testing
  - Social engineering, phishing, physical security testing, credential stuffing, brute force, spam
  - Duplicates, publicly known issues already being remediated, unsupported browsers/software
  - Findings affecting systems Cencora does not own or operate
commitments:
  - Acknowledge receipt of the report
  - Review, validate and risk-assess the issue
  - Coordinate remediation by severity and business impact
  - Provide status updates where appropriate
  - Treat reporter personal information as confidential
disclosure_policy: >-
  Coordinated. Researchers must not publicly disclose until Cencora has had a reasonable
  opportunity to investigate and remediate, and must coordinate any proposed disclosure in advance.
evidence:
  - source: https://www.cencora.com/responsible-disclosure
    kind: disclosure-page
    http_status: 200
    keywords: [responsible disclosure, security vulnerability, safe harbor, good faith, remediation]
  - source: https://www.cencora.com/.well-known/security.txt
    kind: security.txt
    http_status: 404
    note: not served
x-evidence:
  checked: '2026-09-02'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/amerisourcebergen-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.